> Source: [sk119432](https://support.checkpoint.com/results/sk/sk119432)

# sk119432 - Application Control/URL Filtering drops traffic from internal web server

| Property | Value |
|----------|-------|
| Solution ID | sk119432 |
| Date Created | 2017-07-31 |
| Last Modified | 2018-08-12 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Connections to static NAT'd web server do not work.  

* "`fw ctl zdebug + drop`" debug shows that return traffic from the static NAT'd web server is dropped:  

  `[DATE TIME];[cpu_10];[fw4_5];fw_log_drop_ex: Packet proto=6 WebServer_Internal_Address:443 -> ExternalHost:46812 dropped by fwpslglue_chain Reason: PSL Reject: ASPII_MT;`  

* Behaviour may be inconsistent for NAT destinations on different internal interfaces, in that return traffic from some servers may appear to pass correctly, but return traffic through a different interface may be dropped.

## Cause

Application Control/URL Filtering has the host object that is automatically static NATed in the destination column.

Application Control/URL Filtering does not recognize the NAT IP address of the object in the Application Control/URL Filtering rulebase.

If inconsistancies may be present if an internal interface topology "leads to" a large subnet or group of subnets which would overlap with the topology of other interfaces - especially interfaces where "Interface leads to DMZ" is checked, as DMZ inclusion explicitly defines that interface as an External Zone.

Further inconsistancies may be present due to a "leads to" overlap as above, depending on the load order of the interfaces by the OS.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
